In May, Cisco Talos team discovered a RAT dubbed KONNI malware that targets organizations linked to North Korea. The malware, dubbed by researchers KONNI, was undetected for more than 3 years and was used in highly targeted attacks. The current version of the malware allows the operator to steal files, keystrokes, perform screenshots, and execute arbitrary code on the infected host. Experts at Cylance noticed that the decoy document used in the attacks is similar to the one used in recent campaigns of the DarkHotel APT.”]
Source: https://securityaffairs.co/wordpress/61882/hacking/konni-darkhotel-links.html

